Hi,
We keep getting this vulnerabilaty warning from WP Toolkit (Plesk VPS server) (severity is medium). We have the latest version of td composer (5.1) The message is:
tagDiv Composer <= 5.0 – Reflected Cross-Site Scripting via envato_code[]
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_register_forum_user function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Copyright text: Wordfence
Is this something we need to address ourselve, is it something in the code your team needs to fix, or is it a false positive?
If have read older posts about this kind of message on Reflected Cross-Site Scripting, but in all of them you told an update should fix it next time. It’s about a few next times further however, so I am curious if this is a returning vulnerabilaty or just an over excited Wordfence producing a non-issue?
Thanks in advance for your time and efforts regarding this issue.
Probably a bug in Plesk toolbox; since if you’re running 5.1, it probably should not give you warning about “hey, don’t use versions below 5.0).
I stopped using the toolbox on Plesk, myself.
(*it could also be the toolbox needs to be updated from your hosting panel).
-
This reply was modified 1 year by
simchris.
Thanks simchris for making an obvious but valid point regarding the versions mentioned. I will let our tech guy investigate if the update went correctly and if the Plesk toolbox is still needed or just creates a lot of ‘noise’.
Bettina thanks for adding it to your investigation list. Besides the stated above to simchris, we will ingnore this for now.
Please, any update on this? Still appear in version 5.4.3.1 in Plesk
Thanks
Thanks but still appear in my Plesk đ sorry, I see is a Toolkit bug…